Series Part 2 Cloud-to-OnPrem Kubernetes Migration
Author: Zohair Diab | DevOps Engineer | K8s Migration Lab
Reading Time: ~5 minutes
Why Use Talos OS for Kubernetes?
Talos OS is a modern, secure, minimal operating system designed specifically for Kubernetes. Unlike traditional Linux distributions, Talos is immutable, API-driven, and free of unnecessary components — making it lightweight, secure, and purpose-built for container orchestration.
🎯 Key Insight: Talos eliminates the “pets vs cattle” problem at the OS level. Every node is identical, declaratively managed, and can be replaced without manual intervention.
Core Benefits
| Feature | Description |
|---|---|
| Immutability | No SSH, shell, or package manager — reducing attack surface and configuration drift |
| API-Driven | All operations (upgrades, troubleshooting) use a secure API for automation and remote management |
| Consistency | Every node is identical and declaratively managed, ensuring predictable cluster behavior |
| Security | Minimal footprint and locked down by default, following security best practices |
| Easy Upgrades | Seamless, coordinated upgrades and rollbacks for both OS and Kubernetes via talosctl |
Talos OS simplifies Kubernetes infrastructure management, letting you focus on workloads instead of nodes.
Preparing the Environment
In this guide, we will:
- Deploy a 3-node Talos cluster in a Proxmox virtual environment
- Bootstrap Kubernetes on the Talos cluster
- Configure a Virtual IP to load balance requests to the Kubernetes API
- Configure our local machine to access the Kubernetes API
- Deploy and expose an NGINX web server on the cluster
Prerequisites
1 Download the Talos ISO
export TALOS_VERSION=v1.5.3
wget https://github.com/siderolabs/talos/releases/download/$TALOS_VERSION/metal-amd64.iso -O talos-$TALOS_VERSION-amd64.isoUpload this ISO to your Proxmox storage for VM creation.
2 Provision Virtual Machines
Create at least one server or VM. For this demo, we’ll set up 3 VMs with the following specs:
| Resource | Specification |
|---|---|
| CPU | 8 cores per node |
| RAM | 16 GB per node |
| Boot Disk | 32 GB per node |
3 Reserve IPs in DHCP
| Hostname | IP Address |
|---|---|
| cn-1 | 194.36.139.201 |
| cn-2 | 194.36.139.202 |
| cn-3 | 194.36.139.203 |
Install talosctl
# Set Talos version
export TALOS_VERSION=v1.5.3
# Download binarywget https://github.com/siderolabs/talos/releases/download/$TALOS_VERSION/talosctl-linux-amd64
# Make executable and move to PATHchmod +x talosctl-linux-amd64
sudo mv talosctl-linux-amd64 /usr/local/bin/talosctl
# Verify installationtalosctl --version
Creating the Talos Configuration
Step 1: Generate Secrets Bundle
⚠️ Security Warning: The secrets file contains all sensitive information (keys, certificates). Never push this to git unencrypted. Use tools like sops for encryption.
talosctl gen secretsStep 2: Generate Cluster Configuration
The talosctl gen config command requires two parameters:
- Cluster Name: Used for context switching (similar to kubectl contexts). We’ll use
demo-cluster. - Kubernetes Endpoint: The VIP for the Kubernetes API. Since our nodes are
194.36.139.201-203, we’ll use194.36.139.210for the VIP.
talosctl gen config demo-cluster https://194.36.139.200:6443 \
--with-secrets secrets.yaml \
--config-patch @patches/allow-controlplane-workloads.yaml \
--config-patch @patches/cni.yaml \
--config-patch @patches/dhcp.yaml \
--config-patch @patches/install-disk.yaml \
--config-patch @patches/interface-names.yaml \
--config-patch @patches/kubelet-certificates.yaml \
--config-patch-control-plane @patches/vip.yaml \
--output rendered/This generates three files:
| File | Purpose |
|---|---|
controlplane.yaml | Machine config for control-plane nodes |
worker.yaml | Machine config for worker nodes |
talosconfig | Talos equivalent of kubeconfig |
Step 3: Apply Configuration to Nodes
talosctl apply -f rendered/controlplane.yaml -n 194.36.139.201 --insecure
talosctl apply -f rendered/controlplane.yaml -n 194.36.139.202 --insecure
talosctl apply -f rendered/controlplane.yaml -n 194.36.139.203 --insecure💡 Note: talosctl follows the UNIX principle of “no output is good output.” Check the Proxmox VM console — status should change from Maintenance → Booting → Installing.
Configuring talosctl Access
Set Up the Configuration File
# Create .talos directory and copy config
mkdir -p ~/.talos
cp rendered/talosconfig ~/.talos/config
# Or use environment variable
export TALOSCONFIG=./rendered/talosconfig
Configure Endpoints
# Check current context
talosctl config contexts
# Set endpoints (load balances across all control plane nodes)talosctl config endpoint 194.36.139.201 194.36.139.202 194.36.139.203
# Optionally set a default nodetalosctl config node 194.36.139.201
Your context should now look like this:
CURRENT NAME ENDPOINTS NODES
* demo-cluster 194.36.139.201 194.36.139.202 194.36.139.203 194.36.139.201Verify Cluster Members
talosctl get members -n 194.36.139.201Expected output:
NODE NAMESPACE TYPE ID VERSION HOSTNAME MACHINE TYPE OS ADDRESSES
194.36.139.201 cluster Member talos-demo-01 2 talos-demo-01.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.201"]
194.36.139.201 cluster Member talos-demo-02 1 talos-demo-02.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.202"]
194.36.139.201 cluster Member talos-demo-03 1 talos-demo-03.mirceanton.local controlplane Talos (v1.5.4) ["194.36.139.203"]Bootstrapping Kubernetes
Once all Talos nodes have booted and joined the cluster, we can install Kubernetes.
Open Dashboard (Optional but Recommended)
talosctl dashboard -n talos-demo-01Bootstrap the Cluster
talosctl bootstrap -n talos-demo-01Tip: It doesn’t matter which control-plane node you bootstrap from — all nodes are equal after the process completes.
Fetch kubeconfig
talosctl kubeconfig -n talos-demo-01This creates ~/.kube/config automatically. You can now use kubectl:
kubectl get nodesSuccess! Your Talos Kubernetes cluster is now running and accessible via kubectl.
What’s Next?
With Kubernetes running on Talos, you’re ready for the next steps:
- Part 3: Installing Rook-Ceph for distributed storage
- Part 4: Cilium networking and network policies
- Part 5: Velero backup configuration
References
Questions or feedback? Drop a comment below or reach out on LinkedIn. Happy learning!
